Vulnerability Details CVE-2007-6705
The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.1%
CVSS Severity
CVSS v2 Score 3.3
Products affected by CVE-2007-6705
-
cpe:2.3:a:ibm:websphere_mq:*
-
cpe:2.3:a:ibm:websphere_mq:-
-
cpe:2.3:a:ibm:websphere_mq:5.3.1.10
-
cpe:2.3:a:ibm:websphere_mq:5.3.1.11
-
cpe:2.3:a:ibm:websphere_mq:5.3.1.12
-
cpe:2.3:a:ibm:websphere_mq:5.3.1.13
-
cpe:2.3:a:ibm:websphere_mq:5.3.1.14
-
cpe:2.3:a:ibm:websphere_mq:5.3.1.15
-
cpe:2.3:a:ibm:websphere_mq:5.30.0
-
cpe:2.3:a:ibm:websphere_mq:6.0
-
cpe:2.3:a:ibm:websphere_mq:6.0.1.0
-
cpe:2.3:a:ibm:websphere_mq:6.0.1.1
-
cpe:2.3:a:ibm:websphere_mq:6.0.1.2
-
cpe:2.3:a:ibm:websphere_mq:6.0.2.0